Togoder security

npm package security report

@safe-global/safe-gateway-typescript-sdk npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 3.23.1 Files reviewed 22 Size 36.5 KB Scanned

Summary

Togoder Security scanned the npm package @safe-global/safe-gateway-typescript-sdk@3.23.1 on Oct 4, 2026. An AI review of 22 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

Potential SSRF / unrestricted URL fetching

NPS-2856B6279CAF

fetchData and getData accept arbitrary urls and perform fetch calls, potentially allowing requests to internal services if the url is attacker-controlled.

dist/utils.js:57
medium

Credential forwarding

NPS-5299A224E786

credentials parameter is passed directly to fetch options, which may include cookies/auth headers for cross-origin requests; no validation on target origin.

dist/utils.js:75
low

Dynamic RegExp construction

NPS-60E0F5D0F92E

replaceParam builds a RegExp from a key parameter without escaping, which could cause errors or regex injection if keys contain special characters.

dist/utils.js:30

Files reviewed

FileVerdictWhat the reviewer saw
dist/utils.js medium The utility functions appear benign but allow arbitrary network requests and credential forwarding, with minor regex handling concerns; no malicious patterns such as exfiltration or code execution were found.
dist/config.js safe No malicious patterns detected
dist/endpoint.js safe No malicious patterns detected; the code implements straightforward HTTP endpoint wrappers using utility functions with no signs of exfiltration, credential harvesting, obfuscation, or process spawning.
dist/index.js safe No malicious patterns detected; the code is a legitimate Safe API client with standard HTTP endpoint wrappers.
dist/types/accounts.js safe No malicious patterns detected
dist/types/api.js safe No malicious patterns detected
dist/types/auth.js safe The file contains only standard TypeScript/JavaScript export boilerplate and a source map reference with no executable or malicious logic.
dist/types/chains.js safe No malicious patterns detected; the file only defines TypeScript enums for RPC authentication, gas price types, and feature flags with no executable or network-related code.
dist/types/common.js safe No malicious patterns detected
dist/types/contracts.js safe No malicious patterns detected
dist/types/decoded-data.js safe No malicious patterns detected
dist/types/delegates.js safe No malicious patterns detected
dist/types/emails.js safe No malicious patterns detected
dist/types/human-description.js safe No malicious patterns detected
dist/types/master-copies.js safe The file contains only standard TypeScript/JavaScript module boilerplate and a source map reference, with no malicious patterns detected.
dist/types/notifications.js safe No malicious patterns detected
dist/types/recovery.js safe No malicious patterns detected
dist/types/relay.js safe No malicious patterns detected
dist/types/safe-apps.js safe No malicious patterns detected
dist/types/safe-info.js safe No malicious patterns detected
dist/types/safe-messages.js safe No malicious patterns detected
dist/types/transactions.js safe No malicious patterns detected

Scanned versions of @safe-global/safe-gateway-typescript-sdk

VersionVerdictFilesScanned
3.23.1 Needs review 22 Oct 4, 2026

Frequently asked questions

Is @safe-global/safe-gateway-typescript-sdk safe to use?

No confirmed malware was found in @safe-global/safe-gateway-typescript-sdk@3.23.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @safe-global/safe-gateway-typescript-sdk contain malware?

No malware was identified in @safe-global/safe-gateway-typescript-sdk@3.23.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @safe-global/safe-gateway-typescript-sdk checked?

Togoder Security downloaded the published npm package and had an AI model read its 22 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @safe-global/safe-gateway-typescript-sdk together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @safe-global/safe-gateway-typescript-sdk@3.23.1, cost nothing.

Related security reports